Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 95%

Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview

0
High
Published: 06/23/2026 (06/23/2026, 17:23:42 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has released a Technology Preview container image for the satellite/foreman-mcp-server-rhel9, which is designed for advanced reporting and AI-driven data analysis within Red Hat Satellite. This advisory references two CVEs (CVE-2026-9073 and CVE-2026-12112) related to this component. No fixes or patches are currently provided in the advisory. The MCP server container image is intended for local use to generate dynamic reports from Satellite inventory data.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 00:32:16 UTC

Technical Analysis

This advisory concerns the satellite/foreman-mcp-server-rhel9 container image provided by Red Hat Satellite as a Technology Preview. The MCP server facilitates advanced reporting and AI-based data analysis. Two vulnerabilities, CVE-2026-9073 and CVE-2026-12112, are associated with this component. The advisory does not specify technical details of the vulnerabilities beyond referencing CWEs 532 (Information Exposure) and 287 (Improper Authentication). No official fixes or patches are currently available, and the container image is newly introduced as a preview. The advisory directs users to Red Hat Satellite documentation for MCP integration but does not provide remediation steps.

Potential Impact

The vulnerabilities are classified as high severity and involve potential information exposure and authentication issues as indicated by the referenced CWEs. However, no known exploits are reported in the wild at this time. The impact could affect confidentiality and authentication integrity within the MCP server component of Red Hat Satellite, potentially compromising reporting and data analysis functions.

Mitigation Recommendations

No official fixes or patches are currently available for these vulnerabilities as per the Red Hat advisory. Users should monitor Red Hat's official channels for updates and apply any future patches promptly. Since this is a Technology Preview container image, cautious deployment and limiting exposure of the MCP server until a stable, patched release is available is advisable. Refer to Red Hat Satellite documentation for guidance on MCP integration and best practices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:28438
Cve Count
2
Additional Cves
["CVE-2026-12112"]
Cvss Version
3.1

Threat ID: 6a3c0cf2eed863c81e239acc

Added to database: 06/24/2026, 16:59:30 UTC

Last enriched: 08/03/2026, 00:32:16 UTC

Last updated: 08/04/2026, 12:46:14 UTC

Views: 74

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses